---
id: CVE-2026-100294
title: >-
  In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds
  hardcoded cloud‑API credentials that are shared across deployed devices
summary: >-
  In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds
  hardcoded cloud‑API credentials that are shared across deployed devices.
  Anyone obtaining the public firmware package can reuse these values to
  interact with the clo…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-798
vendor: Anjvision
product: YSSD-RTMP-H5
affected:
  - YSSD-RTMP-H5 Version 3.3.2.4 build 2024-12-26
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T22:17:05.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100294'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-29T20:56:38.487671Z'
ingestedAt: '2026-09-29T20:46:06.428Z'
---

## Overview

In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
